patch management
157 stories on patch management, newest first, from 176 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- Two Critical NetScaler Zero-Days Under Active Attack: Patch Now
- Weekly Threat Recap: Citrix Flaws Under Active Attack, Plus a $387M Crypto Heist
- US Cyber Agency Warns of Active Attacks on Critical Citrix NetScaler Flaws
- Citrix NetScaler Under Attack Again: Critical Flaws Being Exploited Right Now
- ACSC Issues Critical Alert on Actively Exploited Citrix NetScaler Vulnerabilities
- Ubuntu Moves to Weekly Kernel Patches as AI-Driven Bug Discovery Overwhelms Defenders
- CISA Pushes for a 'Quality Era' in Vulnerability Reporting as CVE Volumes Surge
- Critical WordPress Flaw Under Active Attack Within Hours of Patch Release
- WordPress Patches Critical Flaw Allowing Unauthenticated Code Execution on Some Sites
- Linux Kernel Bug Lets ARM64 Virtual Machines Peek Into Host Memory
- Mislabelled SharePoint Bug Was Actually a Critical Remote Code Execution Flaw
- Zyxel Switch Flaw Actively Exploited; Veeam Backup Bug Also Under Attack
- AI-Discovered Bugs Pile Up, But Attackers Aren't Rushing to Exploit Them
- SolarWinds Fixes Critical Flaw Letting Attackers Take Over Access Rights Manager Without Login
- Critical Flaw in Orkes Conductor Being Actively Exploited, Patch Now
- Public Exploits Now Available for Four Linux Kernel Root Flaws
- WordPress Patches 'Click2Shell' Flaw That Could Let Attackers Hijack Admin Sessions
- Critical Flaw in Unbound DNS Software Could Let Attackers Run Malicious Code
- Cisco Warns Critical ISE Flaw Is Being Actively Exploited
- Attackers Exploit New Flaws in Days, Businesses Take Weeks to Patch: Why Pentesting Needs to Change
- CISA to Retire Weekly Vulnerability Bulletin as It Shifts to Risk-Based Approach
- Critical Issabel PBX Flaw Under Active Attack: Hard-Coded Key Lets Hackers Run Commands
- Unpatched WooCommerce Plugin Flaw Still Letting Attackers Plant Webshells on WordPress Sites
- CISA Flags Actively Exploited Flaws in Cisco Identity Services Engine and Acronis Backup
- Acronis Warns of Actively Exploited Flaw in cPanel Backup Plugin
- AI Is Finding More Software Flaws Than Ever, But What About Systems You Can't Patch?
- AI Bug-Hunters Are Causing Patching Pain Now, But Could Ease the Load by 2027
- Apple Issues Record-Breaking Security Update: Over 260 Flaws Fixed
- Microsoft Issues Emergency Fix After Patch Tuesday Breaks Remote Desktop Services
-
Critical Cisco Email Gateway Flaw Under Active Attack: Patch Now
Also covered by CISA
-
Critical GitLab Flaw Under Active Attack: Patch Now or Take Servers Offline
Also covered by Infosecurity Magazine, CyberScoop
- Critical Bug Fixed in Bitcoin Lightning Network Development Kit
- Check Point Flags New Protections for Metabase, Windows, GitLab and Chrome Vulnerabilities
- Maximum-Severity GitLab Flaw Under Active Attack Within Hours of Disclosure
- Actively Exploited GitLab Vulnerability Added to US Government Threat List
- PaperCut Rolls Out Full Fixes as Attackers Use AI Agents to Exploit Print Software Flaws
- Check Point Patches Two Critical VPN Certificate Flaws Rated 9.8 Severity
-
Google Patches Actively Exploited Chrome Zero-Day: Update Now
Also covered by Security Week
- cPanel Patches Flaw Letting a Single Mail Account Seize Root Control of Your Server
- SAP Rushes Fix for Maximum-Severity 'Overpass' Flaw Affecting 10,000+ Systems
- Maximum-Severity SAP Flaw Lets Attackers Take Over Systems Without a Password
- CISA Flags Four Actively Exploited Vulnerabilities, Including Windows and Adobe Commerce Flaws
- Critical Magento Flaw Under Active Attack: Patch Now to Block Backdoor Installs
- Weekly Threat Recap: Trusted Software Turned Malicious, Critical N-central Flaws Under Attack
- N-able Patches Critical Flaw in N-central Remote Management Platform
- Public Exploit Released for Telerik UI Flaw Chain Enabling Unauthenticated Server Takeover
- N-able Rushes Out Fourth N-central Hotfix in Five Weeks for Critical Unauthenticated RCE Bug
- MikroTik Router Alert: Attackers Gaining Full Control via Exposed SSH, No Password Needed
- VMware Patches Critical Flaw That Lets VM Users Break Out to the Host Machine
- HPE Fixes Critical Flaws in AOS-CX Switch Software
- PostgreSQL Patches Decade-Old Flaw Allowing Code Execution via Replication Accounts
- Sangoma Switchvox Phone Systems Under Active Attack — Patch Now
- AI-Powered Bug Hunting Is Flooding Vendors With Vulnerability Reports
- 12-Year-Old PostgreSQL Flaw Could Let Attackers Hijack Your Database and Server
- Actively Exploited Chrome Flaw Added to US Government's Must-Patch List
- Critical VMware Flaws Could Let Attackers Break Out of Virtual Machines
- 440,000+ Attacks Target Critical WordPress Plugin Flaws — Is Your Site at Risk?
- Plex Patches Multiple Undisclosed Security Flaws — Update Now
- Critical Security Flaws Found in Citrix NetScaler Devices — Patch Immediately
- Cisco Flags Unpatched Email Encryption Flaws, Rushes Fixes for Critical Switch Bugs
- CISA Flags Seven Actively Exploited Vulnerabilities Used to Plant Reverse Shells and Crypto Miners
- Rockwell Automation Fixes Over a Dozen Security Flaws in Industrial Software
- New Cleo Harmony Vulnerability: Exploit Code Now Public
- SonicWall Patches Two Zero-Day Flaws in SMA 1000 VPN Appliances Actively Exploited by Attackers
- Critical Flaw Chain in GeoNetwork Could Let Attackers Take Over Government Geoportal Systems
-
SonicWall Warns of Two Zero-Day Flaws Under Active Attack in SMA1000 Devices
Also covered by Sophos
-
Hackers Race to Exploit Critical JFrog Artifactory Bug Just Days After Patch Release
Also covered by Security Week
-
Critical Langflow Flaw Under Active Attack — Patch Now
Also covered by The Hacker News, Security Week
- Vendor Launches Real-Time Vulnerability Scanning as Attackers Exploit Flaws Within Hours
- Critical Flaws Found in WatchGuard Firewalls — Patch Now
- CISA Warns: PaperCut Vulnerabilities Now Under Active Attack
- Vulnerability Found in Kaspersky Endpoint Security Now Patched
- ServiceNow Fixes Three Critical Flaws That Could Let Attackers Hijack Systems
-
Urgent: Actively Exploited Vulnerabilities Found in PaperCut Print Management Software
Also covered by The Hacker News
- PaperCut Issues Second Emergency Patch as Attackers Exploit Print Management Software
- Critical WordPress Plugin and Theme Bugs Put Sites at Risk of Takeover
- Critical Flaw in Cosmos EVM Module Exploited to Drain Funds from Six Blockchains
- Urgent Patch Needed: PaperCut Print Software Flaws Let Hackers Take Over Without Login
- AI Agents Used to Exploit Linux Kernel Flaw on OpenAI's Own Systems
- ServiceNow Patches Critical Flaws Rated Maximum Severity — Act Now if You're Self-Hosted
- Critical cPanel Flaw Could Let a Single Hosting Customer Seize Full Server Control
- PaperCut Rushes Out Emergency Fix for Actively Exploited Security Flaw
- Ledger Patches Ethereum App Flaw That Could Have Let Attackers Swap Transactions
-
US Cybersecurity Agency Flags 3 Actively Exploited Software Flaws — Check If You Use Them
Also covered by The Hacker News
- Critical Security Flaws Found in Xiiaozet LK100W Devices
- Urgent: Citrix NetScaler Flaw Under Active Attack — Patch Now
- Adobe and Nvidia Release Critical Security Updates — Patch Now
- CISA Report: Most Cyberattacks Exploit Basic, Known Software Flaws
- CISA Flags Six More Vulnerabilities Under Active Attack
- Google Fixes Over 300 Security Flaws in Latest Chrome Update
- CISA Alerts Businesses to Actively Exploited Gitea Vulnerability
- Security Flaw in Marimo Notebooks Allowed Malicious Commands to Run Automatically
- AI Is Reshaping Vulnerability Management for Businesses of All Sizes
- When Software Fixes Go Quiet: Why 'Silent Patches' Put Businesses at Risk
-
CISA Warns of Active Exploitation of Oracle WebLogic Vulnerability
Also covered by The Hacker News
- Urgent Zimbra Email Flaw Under Attack: Patch Now, Experts Warn
- AI Is Finding Security Flaws Faster Than Businesses Can Fix Them
- CISA Flags Actively Exploited Oracle Server Vulnerability - Patch Now
- Spring Framework Sees Surge in Security Patches: 91 Flaws Fixed This Year
- Critical Keycloak Flaw Lets Hackers Hijack Accounts Without a Password
-
Ledger Fixed a Critical Ethereum Wallet Flaw — But Kept Quiet About It for Two Weeks
Also covered by Crypto Briefing
- Actively Exploited Zimbra Flaw Added to CISA's Must-Patch List
- CISA Warns Businesses to Urgently Patch Exploited TrueConf Software Flaws
- Unpatched Zimbra Servers Under Active Attack: What SMBs Need to Know
- Critical Citrix NetScaler Flaw Lets Attackers Bypass Login — Patch Now
-
Critical GitLab Vulnerability Under Active Attack — Patch Immediately
Also covered by The Hacker News, The Hacker News
- Urgent: Patch Now — Microsoft, VMware and Apple Flaws Under Active Attack
- Oracle Releases Massive Security Update With 943 Patches
- Urgent: Active Attacks Targeting N-able/N-central IT Management Software in Australia
- Decred Cryptocurrency Network Patches Critical Security Flaws
- Multiple Security Flaws Found in CISA's Malcolm Network Monitoring Tool
- SAP Commerce Cloud Under Attack Just Days After Critical Flaw Disclosed
- Critical macOS Flaw Exploited to Secretly Mine Cryptocurrency
- Critical macOS Screen Sharing Bug Actively Exploited to Install Crypto Miners
- AI Is Fueling a Flood of New Vulnerabilities—Can AI Also Help Fix It?
-
Critical VMware vCenter Vulnerability Under Active Global Attack
Also covered by Security Week
- Hackers Move Fast: Adobe Commerce Flaw Exploited Right After Patch Release
- WordPress Patch Fixes Serious Remote Code Execution Flaw
- Siemens License Server Flaws Could Let Attackers Elevate Privileges, Access Files
- Critical Flaw Found in Siemens Video Management Software—Update Now
- Fortinet Fixes Critical Login Flaws in FortiWeb and FortiManager
- New Windows Zero-Day 'ShieldBreak' Lets Attackers Gain Full System Control
-
Hackers Actively Targeting SharePoint Flaw After Exploit Code Goes Public
Also covered by Security Week
- Adobe Issues Urgent Patches for Critical ColdFusion and Campaign Classic Vulnerabilities
- Critical VMware vCenter Flaw Now Under Active Attack, Giving Hackers Persistent Access
- Ivanti Patches Remotely Exploitable Flaws in Endpoint Manager
- Industrial Equipment Makers Patch Security Flaws — Here's What Businesses Should Know
- New 'ShieldBreak' Exploit Bypasses Windows Defender Patch, Grants Full System Access
- Cisco Firewall Flaw Being Actively Exploited to Crash Devices
- Beyond the Checklist: Why Aussie Businesses Need to Rethink How They Patch
-
Urgent Patch Alert: Actively Exploited Flaw Found in Progress LoadMaster Software
Also covered by CISA
- N-able Rushes Second Hotfix as Hackers Continue Targeting N-central RMM Tool
- AI-Written Software Patches Fail Half the Time, Study Finds
- Critical BTCPay Server Flaw Under Active Attack — Update Now
- Decades-Old Linux Kernel Flaw Lets Attackers Escape Containers and Seize Root Access
- Cisco Fixes 12 Security Flaws in SD-WAN and IOS XE Software, Three Rated Critical
- Critical Flaw in Paperclip Software Could Have Let Attackers Seize Admin Control
- US Cybersecurity Agency Warns of Active Attacks on JetBrains TeamCity Servers
- Critical Flaws Patched in Veeam, HashiCorp Terraform MCP, and Django - Update Now
- Actively Exploited JetBrains TeamCity Vulnerability Added to CISA's Must-Patch List
- Linux Kernel Flaw Lets Local Users Seize Full Control of Systems
- US Cyber Agency Warns: Attackers Actively Exploiting Flaws in Popular Business Software
- US Cyber Agency Warns of Active Attacks on Langflow, Tomcat, and N-central Software
- AI-Powered Scanning Uncovers Over 14,000 Hidden Flaws in Open-Source Software
- 15 Security Flaws Found in TP-Link Omada Networking Gear
- cPanel Fixes Critical Flaw Allowing Hosting Customers to Run SQL as Database Root
- N-able Rushes Out Fix After Hackers Bypass Patch for N-central Servers
- Actively Exploited Flaw Found in N-able N-central: What SMBs Using Remote Management Tools Need to Know
- AI Model Autonomously Builds Full Chrome Exploit, Raising Alarm for Defenders
- AI Agents Are Getting Alarmingly Good at Finding and Exploiting Software Bugs
- Research Reveals How Pointer Ordering Can Leak Memory Addresses in Apple Software
- Research Highlights Hidden Risk: How 'Pointer Leaks' Can Undermine Software Security
- Researchers Detail How a Chrome Browser Bug Could Lead to Full System Takeover
- Linux Kernel Flaw Let Attackers Escape Chrome's Security Sandbox
- Google's Project Zero Updates Vulnerability Disclosure Policy for 2025
- Google Project Zero Adds Early Disclosure Step to Speed Up Security Patches
- Deep-Dive Research Exposes How Windows Registry Flaws Can Be Exploited